CVE-2026-56164

critical

Description

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

From the Tenable Blog

SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable®
SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable®

Published: 2026-07-16

CISA confirmed exploitation of three SharePoint Server CVEs. Patches, AMSI IoCs, and details on CVE-2026-32201, CVE-2026-45659, CVE-2026-56164.

July 2026 Patch Tuesday: Largest Patch Tuesday 569 CVEs
July 2026 Patch Tuesday: Largest Patch Tuesday 569 CVEs

Published: 2026-07-14

Microsoft patched 569 CVEs in July 2026, the largest Patch Tuesday release in its history. 56 critical CVEs patched including three zero-day vulnerabilities.

References

https://www.securityweek.com/fourth-sharepoint-vulnerability-exploited-in-past-months-wave-of-attacks/

https://www.helpnetsecurity.com/2026/07/22/sharepoint-cve-2026-50522-exploited/

https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html

https://www.securityweek.com/fresh-sharepoint-vulnerability-exploited-soon-after-disclosure/

https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html

https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-sharepoint-vulnerabilities/

https://www.infosecurity-magazine.com/news/microsoft-570-cves-patch-tuesday/

https://www.bleepingcomputer.com/news/security/cisa-warns-admins-to-patch-actively-exploited-sharepoint-flaws/

https://therecord.media/microsoft-vulnerabilities-patch-tuesday-release

https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html

https://securityaffairs.com/195383/security/u-s-cisa-adds-sonicwall-and-microsoft-flaws-to-its-known-exploited-vulnerabilities-catalog.html

https://hackread.com/microsoft-july-2026-patch-tuesday-fixes-zero-days/

https://www.theregister.com/security/2026/07/14/patchpocalypse-now-microsoft-tops-last-months-record-with-622-patch-tuesday-cves/5271434

https://www.securityweek.com/microsoft-patches-record-622-vulnerabilities-including-two-exploited-zero-days/

https://www.darkreading.com/vulnerabilities-threats/records-broken-patch-tuesday-raises-triage-stakes

https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations

https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalog

https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html

https://securityaffairs.com/195347/security/patch-tuesday-security-updates-for-july-2026-the-largest-update-ever-621-cves-in-one-month.html

https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/

https://cyberscoop.com/microsoft-patch-tuesday-july-2026/

Details

Source: Mitre, NVD

Published: 2026-07-14

Updated: 2026-07-14

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.18395